CVE-2025-25916: XSS
Published Feb 28, 2025
·Updated
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
Affected Software
2 affected components
Wuzhicms Wuzhicms
Wuzhicms Wuzhicms=4.1.0
Event History
Feb 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25916?
CVE-2025-25916 has a moderate severity rating due to its Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-25916?
To fix CVE-2025-25916, it's recommended to sanitize user inputs in the del function in \coreframe\app\member\admin\group.php.
3
What software is affected by CVE-2025-25916?
CVE-2025-25916 affects WuzhiCMS version 4.1.0.
4
What type of vulnerability is CVE-2025-25916?
CVE-2025-25916 is classified as a Cross Site Scripting (XSS) vulnerability.
5
What can attackers do with CVE-2025-25916?
Attackers exploiting CVE-2025-25916 could execute arbitrary scripts in the context of the user's session, potentially leading to data theft.